stop on BITS download errors

reject 0 byte dsa-collector.exe before launching
This commit is contained in:
2026-09-30 09:46:37 -04:00
parent 35c1904d0d
commit 4e6c35a8f4
6 changed files with 119 additions and 5 deletions
+64
View File
@@ -0,0 +1,64 @@
#Requires -Version 5.0
# Offline regression tests. BITS and URL resolution are mocked.
$ErrorActionPreference = 'Stop'
$DownloadToolsPath = Join-Path (Split-Path $PSScriptRoot -Parent) 'Tools.ps1'
$DownloadTokens = $null
$DownloadParseErrors = $null
$DownloadAst = [Management.Automation.Language.Parser]::ParseFile($DownloadToolsPath, [ref]$DownloadTokens, [ref]$DownloadParseErrors)
If ($DownloadParseErrors.Count) { Throw ($DownloadParseErrors | Out-String) }
$DownloadDefinition = $DownloadAst.Find({
param($Node)
$Node -is [Management.Automation.Language.FunctionDefinitionAst] -and $Node.Name -eq 'Download-File'
}, $true)
. ([scriptblock]::Create($DownloadDefinition.Extent.Text))
Function Get-AbsoluteURI { param($URL) Return $URL }
Function Start-BitsTransfer {
[CmdletBinding()]
param($Source, $Destination)
If ($script:DownloadTestMode -eq 'success') {
[IO.File]::WriteAllText($Destination, 'Synthetic download.')
Return
}
[IO.File]::WriteAllBytes($Destination, [byte[]]@())
If ($script:DownloadTestMode -eq 'terminating-error') { Throw 'Synthetic BITS connection failure.' }
Microsoft.PowerShell.Utility\Write-Error 'Synthetic BITS TLS failure.'
}
$DownloadTestRoot = Join-Path ([IO.Path]::GetTempPath()) ('download-file-tests-' + [guid]::NewGuid().ToString('N'))
$null = New-Item -Path $DownloadTestRoot -ItemType Directory
Try {
$DownloadTestFile = Join-Path $DownloadTestRoot 'collector $test.exe'
$script:DownloadTestMode = 'success'
$DownloadResult = Download-File -URL 'https://example.invalid/collector.exe' -File $DownloadTestFile
If ($DownloadResult -cne $DownloadTestFile -or [IO.File]::ReadAllText($DownloadResult) -cne 'Synthetic download.') {
Throw 'Successful download did not return the completed file.'
}
Write-Host 'PASS: successful download returns its destination.'
Foreach ($script:DownloadTestMode in @('nonterminating-error','terminating-error')) {
# Match an RMM that uses the normal Continue preference and does not pass -ErrorAction.
$ErrorActionPreference = 'Continue'
$DownloadCaught = $null
$DownloadReturnedPaths = @()
Try {
Download-File -URL 'https://example.invalid/collector.exe' -File $DownloadTestFile |
ForEach-Object { $DownloadReturnedPaths += $_ }
}
Catch { $DownloadCaught = $_ }
Finally { $ErrorActionPreference = 'Stop' }
If ($null -eq $DownloadCaught -or $DownloadCaught.Exception.Message -notlike '*Synthetic BITS*failure*') {
Throw 'Failed transfer must throw and preserve the BITS error.'
}
If ($DownloadReturnedPaths.Count -ne 0) { Throw 'Failed transfer returned a success path.' }
Write-Host "PASS: $script:DownloadTestMode stops the caller and preserves the transfer error."
}
Write-Host "All Download-File tests passed on PowerShell $($PSVersionTable.PSVersion), $([IntPtr]::Size * 8)-bit."
}
Finally {
$DownloadResolvedRoot = (Resolve-Path -LiteralPath $DownloadTestRoot).Path
$DownloadTempRoot = [IO.Path]::GetFullPath([IO.Path]::GetTempPath()).TrimEnd('\') + '\'
If (!$DownloadResolvedRoot.StartsWith($DownloadTempRoot, [StringComparison]::OrdinalIgnoreCase) -or
(Split-Path $DownloadResolvedRoot -Leaf) -notlike 'download-file-tests-*') { Throw 'Unexpected cleanup directory.' }
Remove-Item -LiteralPath $DownloadResolvedRoot -Recurse -Force
}
+16 -1
View File
@@ -13,12 +13,18 @@ Function Download-File {
[CmdletBinding()]
param($URL, $File)
$script:DsaDownloadCalls++
If ($script:DsaTestMode -eq 'empty-download') {
[IO.File]::WriteAllBytes($File, [byte[]]@())
Return $File
}
If ($script:DsaTestMode -eq 'download-failure') { Throw 'Simulated BITS failure.' }
[IO.File]::WriteAllText($File, 'Mock executable; never executed.')
Return $File
}
Function Start-Process {
[CmdletBinding()]
param($FilePath, $ArgumentList, [switch]$Wait, [switch]$PassThru, $WindowStyle)
$script:DsaProcessCalls++
$DsaMatch = [regex]::Match($ArgumentList, '"--output"\s+"([^"]+)"')
If (!$DsaMatch.Success) { Throw 'Collector output argument missing.' }
$script:DsaCsvPath = $DsaMatch.Groups[1].Value
@@ -64,6 +70,7 @@ Function Invoke-DsaCase {
$script:DsaTestMode = $Mode
$script:DsaRecordedUploads = @()
$script:DsaDownloadCalls = 0
$script:DsaProcessCalls = 0
$script:DsaGeneratedPath = $null
$DsaCaught = $null
Try { . $DsaScriptUnderTest | Out-Null } Catch { $DsaCaught = $_ }
@@ -73,6 +80,14 @@ Function Invoke-DsaCase {
Assert-Dsa ($script:DsaDownloadCalls -eq 0) 'Invalid flag must fail before downloading.'
Return
}
If ($Mode -in @('empty-download','download-failure')) {
Assert-Dsa ($null -ne $DsaCaught) 'Download failure must stop collection.'
Assert-Dsa ($script:DsaProcessCalls -eq 0 -and $script:DsaRecordedUploads.Count -eq 0) 'Download failure must prevent execution and upload.'
If ($Mode -eq 'empty-download') {
Assert-Dsa ($DsaCaught.Exception.Message -like '*0 bytes*') 'Empty download error must explain the failure.'
}
Return
}
If ($Mode -in @('collector-failure','missing-output')) {
Assert-Dsa ($null -ne $DsaCaught -and $script:DsaRecordedUploads.Count -eq 0) 'Collection failure must prevent upload.'
Return
@@ -107,7 +122,7 @@ Try {
Write-Host "PASS: ZIP=$ZipExpected Upload=$UploadExpected DeleteAfterUpload=$DeleteExpected"
}
}
Foreach ($Mode in @('upload-failure','no-receipt','incomplete-receipt','collector-failure','missing-output')) {
Foreach ($Mode in @('upload-failure','no-receipt','incomplete-receipt','collector-failure','missing-output','empty-download','download-failure')) {
Invoke-DsaCase $ZipExpected $true $true $Mode
Write-Host "PASS: ZIP=$ZipExpected $Mode prevents deletion."
}